These matters have been debated for a long time, but recently there has again been increased activity around me aimed at clarifying the meaning of terms such as “de-identification” and “anonymization.” The immediate catalyst was, in June 25 this year, the Study Group on the Use and Application of Personal Data of the Ministry of Internal Affairs and Communications publishing its report (hereafter, the MIC Report).
Of particular note in this report is the passage on page 33 stating: “Taking into account approaches at the U.S. FTC such as those found in the U.S. FTC’s March 2012 report on a framework for the conduct of companies that collect and use consumer data, ‘Protecting Consumer Privacy in an Era of Rapid Change’ (author’s note: hereafter, the FTC Report), it is considered possible to organize the matter such that, when all of the following conditions are met, the data can be used without obtaining the individual’s consent because it lacks substantive personal identifiability and therefore does not constitute protected personal data.” I will call these the MIC 3 requirements. They are as follows.
- Appropriate anonymization measures have been applied.
- The organization pledges and publicly declares that it will not re-identify anonymized data.
- When anonymized data is provided to a third party, the recipient is contractually prohibited from re-identifying it.
When both data de-identified through anonymization and the original identifiable data (including correspondence tables used in linkable anonymization) are retained and used, these data should be stored separately.
(Source) Report of the MIC Study Group on the Use and Application of Personal Data, p. 33
As the MIC Report itself notes, this closely resembles what are commonly called the “FTC 3 requirements.”
The FTC’s 3 requirements specify that a company must satisfy the following 3 requirements for it not to have to apply the safeguards required by the FTC Report to the data—in other words, to treat the data as “not reasonably linkable to a particular consumer, computer, or other device.”
- The company must take reasonable measures to de-identify the data.
- The company must publicly commit not to re-identify the data.
- The company must contractually prohibit any recipient of the data, whether a contractor or third party, from re-identifying it.
When both the de-identified data and the original identifiable data are retained and used, these data should be stored separately.
(These 3 requirements were introduced in response to frequent criticism in public comments on an earlier draft report that it was unclear what would qualify data as not reasonably linkable to a particular consumer or device.)
Regarding the first of the 1 requirements, the FTC Report provides an explanation on page 21, beginning at line 3, in paragraphs 2 and 3. In brief, they say that what constitutes reasonable de-identification must be determined case by case based on factors including the intended use of the data and the technology available at the time.
The next of the 2 requirements—the public commitment not to re-identify the data—is intended to enable the FTC to take action under Section 5 of the FTC Act if the company attempts to re-identify the data (takes steps to re-identify such data). It is, so to speak, a condition for ensuring enforceability. This is described on page 21, paragraph 4, of the report.
The last of the 3 requirements is a provision designed to prevent re-identification by a transferee using a method the company did not anticipate when it de-identified the data. It is described on page 21, paragraph 5, of the report. Along with this, the report requires reasonable monitoring of compliance so that appropriate action can be taken if a violation occurs. Someone who reads requirement 3 without reading the explanation would not know this. Therefore, when I present requirement 3 below, I will include this point as well.
As is apparent at a glance, “de-identification” and “re-identification” play extremely important roles. It is therefore essential to understand precisely what they mean.
The Netflix Case
In the following paragraph, the FTC Report attempts to explain these concepts using the FTC’s closing letter concerning the Netflix case.
In that case, the FTC intervened to stop Netflix, the largest online video-rental company in the United States, from releasing “purportedly anonymous consumer data.” What does a case involving “purportedly anonymized” data—in other words, data that was not actually anonymized and therefore not de-identified—look like?
The case concerned a contest Netflix planned to hold in 2009 to create a better movie-recommendation algorithm. The FTC expressed concerns, and the contest was ultimately canceled. The FTC’s concerns originated in research concerning a similar contest Netflix had held in 2006.
In the contest held in 2006 (Prize 1), Netflix provided the ratings viewers had given each movie and the dates of those ratings for 480,000 people in order to improve recommendation algorithms (the Prize 1 dataset). To “anonymize” the dataset, viewers’ names were replaced with unique numbers, and addresses, telephone numbers, and other direct identifiers were removed.
After the contest, however, researchers at the University of Texas published research findings showing that by adding only a small amount of data, it was possible to determine who a viewer was and extract which movies that viewer had rated during a given period. The findings were also covered by the media and others.
Nevertheless, in 2009 Netflix sought to hold a similar contest, this time using “anonymous data” consisting of viewers’ viewing histories, preference settings, and some demographic data. Because this dataset would contain more information than the one from 2006, it was considered to pose a non-negligible risk of re-identification, leading to the FTC’s letter of November 2009. (The FTC urges businesses to be especially careful when using terms such as “anonymized” or “non-personally identifiable information” in communications to consumers.) In light of concerns about re-identification and representations Netflix had previously made concerning the disclosure of consumer information, the letter expressed concerns under Section 5 of the FTC Act.
As a result, (1) Netflix discontinued the contest and release of the data; (2) if it were to provide the data in the future, it would do so only to certain researchers and solely for specified purposes; (3) in that event, it would impose contractual restrictions and take operational measures to prevent the data from being re-identified; and (4) in that event, it would consult the FTC in advance. The matter was thereby resolved.
Linkability, De-identification, and Re-identification
From these facts, we can understand the following.
A. For data to be considered not reasonably linkable to a particular consumer or device, it must satisfy the FTC’s 3 requirements
This is clear because the FTC’s 3 requirements constitute the definition itself.
B. Replacing names and other identifiers with other identifiers (pseudonymization) is not recognized as anonymization
The Netflix case shows that the FTC does not regard replacing names and other identifiers with other identifiers as anonymization. This is evident because the FTC described Netflix’s replacement process in this case as “purportedly anonymous.” “Purportedly” means, in effect, “you did not actually do it.” My translation above may be too gentle to make the point obvious, but alternative renderings would be “falsely claimed to be anonymized” or “of doubtful anonymization.” You understand now, don’t you? There is in fact another term for this process: pseudonymization.
C. Pseudonymization is not recognized as reasonable de-identification
In the Netflix case, Netflix had pseudonymized the dataset. The FTC, however, said this was unacceptable because of the strong risk that it could be re-identified. In other words, it concluded that the first of the FTC’s 3 requirements, requirement 1, was not satisfied, and therefore that the data had not been reasonably de-identified.
D. The entity responsible for de-identification is the company concerned
This is clear from the FTC’s 3 requirements, specifically requirement 1.
E. Re-identification must be prohibited for the company concerned and for every recipient of the data, including contractors
This is clear from requirements 2 and 3.
Differences Between the MIC’s 3 Requirements and the FTC’s 3 Requirements
Now let us look once again at the MIC’s 3 requirements and the FTC’s 3 requirements.
MIC 3 requirements
- Appropriate anonymization measures have been applied.
- The organization pledges and publicly declares that it will not re-identify anonymized data.
- When anonymized data is provided to a third party, the recipient is contractually prohibited from re-identifying it.
When both data de-identified through anonymization and the original identifiable data (including correspondence tables used in linkable anonymization) are retained and used, these data should be stored separately.
FTC 3 requirements
For a dataset to be considered not reasonably linkable to a particular consumer or device, the following requirements must be met:
- The company must take reasonable measures to de-identify the data.
- The company must publicly commit not to re-identify the data.
- The company must contractually prohibit recipients of the data, whether contractors or third parties, from re-identifying it, and must reasonably monitor compliance so that appropriate action can be taken if a violation occurs.
When both the de-identified data and the original identifiable data are retained and used, these data should be stored separately.
The first thing we can say is that both sets of requirements emphasize de-identification. The MIC’s 3 requirements refer to anonymization measures, but the text below says “de-identified through anonymization,” showing that anonymization is one means of de-identification. Thus, requirement 1 would mean the same thing if phrased as “appropriate de-identification measures have been applied.” In other words, although requirement 1 is worded differently, its intended meaning is likely the same. However, it will be necessary to verify going forward that there is no discrepancy between what the FTC Report and the MIC Report mean by “de-identification.” The FTC, meanwhile, avoids the word “anonymization,” perhaps in recognition that it is often used ambiguously and incorrectly. In a sense, that is wise.
Requirement 2 is similarly worded, but its effect appears to differ. Even if MIC requirement 2 exists, it presumably does not contemplate the MIC taking enforcement action against a business. FTC requirement 2, by contrast, was included so that the FTC could secure legal enforceability. FTC requirement 2 can therefore be said to have considerably stronger effect.
Requirement 3 is also substantially stronger on the FTC side. Reading only the heading-like wording of requirement 3 in the FTC Report—“contractually prohibit a recipient of the data from re-identifying it”—it may appear equivalent to MIC requirement 3, but FTC requirement 3 includes reasonable monitoring and action in its latter half.
It follows that the MIC’s 3 requirements are considerably looser and more business-friendly than the FTC’s 3 requirements.
Next Time…
This has become quite long. This time, I examined in some detail what the FTC means by reasonably unlinkable. Next time, I would like to consider the object of that phrase: “a particular consumer, computer, or device.”
Related posts

Data Sustains Lives—MyDataConference 2026 Opening Address
The following is the opening address for the MyData Japan Conference 2026, delivered by Nat Sakimura in his capacity as Chair of the General Incorporated Association…

The MyData Conference 2026 Is This Wednesday. See You at Hitotsubashi Hall!
I have been posting announcements on X every few days, and the MyDataJapan Conference 2026 is this Wednesday. There are many highlights: Naohiro Fujie, Representative Director…

Unsubmitted Public Comment on the Call for Comments on the Draft First Report of the Youth Protection Working Group on Information Distribution in the Digital Space
July 823:59 was the deadline for the call for comments on the draft first report. I ended the FAPI WG early and23:40 began the submission process…
